An Authority to Operate is a risk decision, not a certificate. The authorizing official (AO) signs to accept the residual risk of running a system on a DoD network. Everything in the Risk Management Framework exists to give that official enough evidence to sign with confidence.
DoD implements RMF through DoD Instruction 8510.01, built on NIST SP 800-37 Revision 2. The work runs in seven steps, and most of the record lives in eMASS, the Enterprise Mission Assurance Support Service.
The seven RMF steps
| Step | What it produces |
|---|---|
| 1. Prepare | Roles assigned (AO, security control assessor, ISSM, ISSO, system owner), the authorization boundary, and organization-wide risk strategy. |
| 2. Categorize | The system's impact level for confidentiality, integrity and availability. DoD uses CNSSI 1253 for this. |
| 3. Select | The NIST SP 800-53 control baseline, tailored with overlays and documented in the System Security Plan (SSP). |
| 4. Implement | Controls built into the system and described as implemented, including STIG configuration. |
| 5. Assess | Independent testing by the assessor, recorded in the Security Assessment Report (SAR). |
| 6. Authorize | The AO's decision: ATO, ATO with conditions, an Interim Authority to Test (IATT), or denial. |
| 7. Monitor | Continuous monitoring, POA&M updates and change review that keep the authorization valid. |
Where ATO packages stall
1. A boundary nobody agrees on
If the authorization boundary is vague, every later artifact is wrong. Interconnections get missed, inherited controls get claimed twice, and the assessor sends the package back. Settle the boundary diagram and the interconnection list in the Prepare step, and get the ISSM and system owner to sign it.
2. Control narratives that restate the control
An implementation statement that repeats the control text tells the assessor nothing. A good statement names who does what, with which tool, how often, and where the evidence lives. Assessors test what you say you do, so say exactly what you do.
3. Scan results that don't match the POA&M
The ACAS findings, the STIG checklists and the POA&M must tell one story. When a scan shows a finding the POA&M doesn't carry, the assessor stops trusting the rest of the package. Reconcile all three before you submit.
4. Treating authorization as the finish line
Programs that sprint to the signature and then stop monitoring end up re-authorizing from scratch. The Monitor step is where an ATO is kept. We cover that operating model in our white paper, Keeping the ATO.
Who does the work
The ISSO carries most of the daily load: maintaining the SSP, tracking POA&M items, reviewing changes for security impact and keeping eMASS current. The ISSM oversees one or more systems and ties them to the organization's risk posture. When those seats are filled with senior practitioners, the package reaches the assessor clean the first time.
Sources: NIST SP 800-37 Rev. 2 · DoD Instruction 8510.01 (DoD Issuances) · NIST SP 800-53 Rev. 5
- Risk Management Framework
- RMF
- ATO
- Authority to Operate
- eMASS
- DoDI 8510.01
- NIST SP 800-37
- NIST SP 800-53
- ISSO
- ISSM
Need this done on your program?
Winston & Miller supports primes and program offices across the National Capital Region with RMF, ATO, ISSO/ISSM and CMMC work.
Request a capability statement